Skip to content

Drop sprintf-js from the dev dependency tree - #127

Merged
arvida merged 1 commit into
mainfrom
fix/sprintf-js-dev-dependency
Oct 9, 2026
Merged

arvida merged 1 commit into
mainfrom
fix/sprintf-js-dev-dependency

Conversation

@arvida

@arvida arvida commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Fixes Dependabot alert #70 (sprintf-js <= 1.1.3, denial of service through unbounded precision specifiers). Dev-only: it never shipped in the package.

Why an override, not a bump

Every published sprintf-js version is affected, so there is nothing to upgrade to. It came in through Jest's coverage tooling:

ts-jest → @jest/transform → babel-plugin-istanbul@6 → @istanbuljs/load-nyc-config → js-yaml@3 → argparse@1 → sprintf-js

js-yaml@3 only uses argparse in its command-line binary (bin/js-yaml.js), never in the library that loads the nyc config. A scoped override points that one dependency at argparse@2, which has no sprintf-js:

"overrides": {
  "js-yaml@3": {
    "argparse": "^2.0.1"
  }
}

Jest and ts-jest stay on 29. No runtime dependency changes. The lockfile also picks up engines: >=20.0.0, which package.json already says.

Verified

  • npm ls sprintf-js is empty; npm ls argparse shows only 2.0.1.
  • npm audit: 41 findings to 36, no moderates left.
  • npm test: 83 suites, 1506 tests pass, also with --coverage (the path this touches). tsc --noEmit and lint are clean.
  • npm pack --dry-run: the same 145 files as main.

Not in this PR

npm audit still lists handlebars (critical) and braces (high), both dev-only through Jest 29. Clearing them means moving to Jest 30.

- Override argparse to ^2.0.1 under js-yaml@3, which reaches us via ts-jest -> babel-plugin-istanbul -> @istanbuljs/load-nyc-config
- js-yaml 3 only uses argparse in its CLI binary, not the library; argparse 2 has no sprintf-js and keeps camelCase shims, so that binary still runs (with deprecation warnings)
- Clears the sprintf-js unbounded precision DoS advisory, which has no patched release
- Lockfile also picks up the engines field (>=20.0.0) that package.json already declared
@arvida
arvida merged commit 1094144 into main Oct 9, 2026
1 check passed
This was referenced Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant